News: 1679470330

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Unknown actors deploy malware to steal data in occupied regions of Ukraine

(2023/03/22)


A cyber espionage campaign targeting organizations in Russian-occupied regions of Ukraine is using novel malware to steal data, according to Russia-based infosec software vendor Kaspersky.

In a [1]report published Tuesday, Kaspersky researchers detailed the infections, which use a PowerShell-based backdoor they've named "PowerMagic" and a previously unknown framework dubbed "CommonMagic" that can steal files from USB devices, take screenshots every three seconds, and send all of this data back to the attacker.

Kaspersky says the cyber snoops, which have been active since at least September 2021, don't share infrastruture, code, or other direct ties to any known advanced persistent threat (APT) groups. However, the victims – administrative, agricultural and transportation organizations located in the Donetsk, Luhansk and Crimea regions – and the phishing lures suggest that this campaign is related to the illegal Russian invasion of Ukraine.

[2]

"Geopolitics always affect the cyber threat landscape and lead to the emergence of new threats," Leonid Besverzhenko, security researcher at Kaspersky's Global Research and Analysis Team, explained in a [3]statement . "We have been monitoring activity connected to the conflict between Russia and Ukraine for a while now, and this is one of our latest discoveries."

[4]

[5]

While the malware and techniques used by the threat actors "are not particularly sophisticated," the use of cloud storage for command-and-control infrastructure is notable, Besverzhenko added.

"We will continue our investigation and hopefully will be able to share more insights into this campaign," he said.

[6]Got Conti? Here's the ransomware cure to avoid paying up

[7]Microsoft: Patch this severe Outlook bug that Russian miscreants exploited

[8]Putin to staffers: Throw out your iPhones, or 'give it to the kids'

[9]Google: Turn off Wi-Fi calling, VoLTE to protect your Android from Samsung hijack bugs

The research team first spotted the infection in October 2022, and suspect it starts with a spearphishing email directing the victim to a URL that points to a .zip archive on a malicious web server.

The archive contains two files. The first is a decoy document, crafted to trick the victim into thinking the content is legitimate by using regional topics and titles. There's a screenshot in Kaspersky's research showing one of these decoy Word documents, titled "Results of the State Duma elections in the Republic of Crimea".

[10]

The second is the baddy: a malicious .lnk file that, when opened, infects the victim's device with the PowerMagic backdoor.

The backdoor communicates with a public-cloud-storage based command-and-control server, executing commands from the server on the infected machine and uploading the results back to the cloud.

It uses OneDrive and Dropbox folders as transport, and OAuth refresh tokens as credentials, according to Kaspersky.

[11]

The researchers suggest that PowerMagic also deploys a modular framework called CommonMagic. So far, they've discovered two malicious plugins being executed by the framework. One – S[.]exe – takes screenshots every three seconds using the GDI API, and the other – U[.]exe – steals files from connected USB devices.

According to the researchers, "the campaign is still active, and our investigation continues." They believe that "further discoveries may reveal additional information about this malware and the threat actor behind it." ®

Get our [12]Tech Resources



[1] https://securelist.com/bad-magic-apt/109087/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZBrf11NF6zhCXukTXUBE9AAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://usa.kaspersky.com/about/press-releases/2023_kaspersky-uncovers-ongoing-apt-campaign-targeting-organizations-in-russian-ukrainian-conflict-area

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBrf11NF6zhCXukTXUBE9AAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBrf11NF6zhCXukTXUBE9AAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/03/16/kaspersky_conti_decryptor/

[7] https://www.theregister.com/2023/03/14/microsoft_patch_tuesday/

[8] https://www.theregister.com/2023/03/21/kremlin_iphone_ban/

[9] https://www.theregister.com/2023/03/17/android_google_project_zero_samsung_modems/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBrf11NF6zhCXukTXUBE9AAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBrf11NF6zhCXukTXUBE9AAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



Peter2

However, the victims – administrative, agricultural and transportation organizations located in the Donetsk, Luhansk and Crimea regions – and the phishing lures suggest that this campaign is related to the illegal Russian invasion of Ukraine.

Well, quite.

Ok, so transportation organisations I completely understand wanting to spy on; saying where cargo [especially military cargo; ie Russian ammunition] is being picked up and delivered to has very obvious military applications; helping Russian ammo stockpiles explode in the warehouse rather than after being delivered to and fired by the Russians.

Administrative makes general sense as there might be usable information [We are going to use building X for R&R for Russian troops between X and Y dates = legitimate military target], however i'm not seeing any particularly obvious reason as to why they would care much about agricultural organisations.

Can anybody see what i'm missing? Perhaps X food amount is being delivered to Y location gives Russian troop strengths?

MiguelC

Don't you know of any other uses for fertilisers? If you don't, [1]Timothy McVeigh might enlighten you

[1] https://www.fbi.gov/history/famous-cases/oklahoma-city-bombing

Potemkine!

What is interesting here is to have the IoC and the means used to infect the devices.

About the threat actors, no one can be excluded, Putin Khuylo is paranoid enough to spy his own puppets.

If we all work together, we can totally disrupt the system.